From deb95e79ca495beb70d1be87b41f53a6a7dd03e0 Mon Sep 17 00:00:00 2001 From: Ganawa Juanah Date: Sat, 8 Oct 2022 16:19:31 -0500 Subject: firewall: correct rule-set interface assignment --- docs/configuration/firewall/general.rst | 12 ++++++------ 1 file changed, 6 insertions(+), 6 deletions(-) (limited to 'docs') diff --git a/docs/configuration/firewall/general.rst b/docs/configuration/firewall/general.rst index cfd7a8ce..8851cc2a 100644 --- a/docs/configuration/firewall/general.rst +++ b/docs/configuration/firewall/general.rst @@ -591,17 +591,17 @@ A Rule-Set can be applied to every interface: * ``out``: Ruleset for forwarded packets on an outbound interface * ``local``: Ruleset for packets destined for this router -.. cfgcmd:: set interface ethernet firewall [in | out | local] - [name | ipv6-name] +.. cfgcmd:: set firewall interface [in | out | local] [name | ipv6-name] + Here are some examples for applying a rule-set to an interface .. code-block:: none - set interface ethernet eth1 vif 100 firewall in name LANv4-IN - set interface ethernet eth1 vif 100 firewall out name LANv4-OUT - set interface bonding bond0 firewall in name LANv4-IN - set interfaces openvpn vtun1 firewall in name Lanv4-IN + set firewall interface eth1.100 in name LANv4-IN + set firewall interface eth1.100 out name LANv4-OUT + set firewall interface bond0 in name LANv4-IN + set firewall interfac vtun1 in name LANv4-IN .. note:: As you can see in the example here, you can assign the same rule-set to -- cgit v1.2.3 From 8f9aa4476d8ea71b128855a52e640e3aea782928 Mon Sep 17 00:00:00 2001 From: Ganawa Juanah Date: Sat, 8 Oct 2022 16:21:44 -0500 Subject: firewall: correct firewall example --- docs/configuration/firewall/general.rst | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) (limited to 'docs') diff --git a/docs/configuration/firewall/general.rst b/docs/configuration/firewall/general.rst index 8851cc2a..7edd9e64 100644 --- a/docs/configuration/firewall/general.rst +++ b/docs/configuration/firewall/general.rst @@ -815,6 +815,11 @@ Example Partial Config .. code-block:: none firewall { + interface eth0 { + in { + name FROM-INTERNET + } + } all-ping enable broadcast-ping disable config-trap disable @@ -871,11 +876,6 @@ Example Partial Config address dhcp description OUTSIDE duplex auto - firewall { - in { - name FROM-INTERNET - } - } } } -- cgit v1.2.3 From 80dc663e5d67e51c7835db299db67e1fcb81bb85 Mon Sep 17 00:00:00 2001 From: Ganawa Juanah Date: Sat, 8 Oct 2022 16:23:59 -0500 Subject: firewall: correct typo --- docs/configuration/firewall/general.rst | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) (limited to 'docs') diff --git a/docs/configuration/firewall/general.rst b/docs/configuration/firewall/general.rst index 7edd9e64..8e093c1d 100644 --- a/docs/configuration/firewall/general.rst +++ b/docs/configuration/firewall/general.rst @@ -601,7 +601,7 @@ A Rule-Set can be applied to every interface: set firewall interface eth1.100 in name LANv4-IN set firewall interface eth1.100 out name LANv4-OUT set firewall interface bond0 in name LANv4-IN - set firewall interfac vtun1 in name LANv4-IN + set firewall interface vtun1 in name LANv4-IN .. note:: As you can see in the example here, you can assign the same rule-set to -- cgit v1.2.3 From 1b1e930a22beacad2154d043b5eccbdf4481503b Mon Sep 17 00:00:00 2001 From: Ganawa Juanah Date: Sat, 8 Oct 2022 16:32:49 -0500 Subject: firewall: reduce line ending in rule-set --- docs/configuration/firewall/general.rst | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) (limited to 'docs') diff --git a/docs/configuration/firewall/general.rst b/docs/configuration/firewall/general.rst index 8e093c1d..efd5cb58 100644 --- a/docs/configuration/firewall/general.rst +++ b/docs/configuration/firewall/general.rst @@ -591,7 +591,8 @@ A Rule-Set can be applied to every interface: * ``out``: Ruleset for forwarded packets on an outbound interface * ``local``: Ruleset for packets destined for this router -.. cfgcmd:: set firewall interface [in | out | local] [name | ipv6-name] +.. cfgcmd:: set firewall interface [in | out | local] [name | ipv6-name] + Here are some examples for applying a rule-set to an interface -- cgit v1.2.3 From 7118b6119f8be5a31b4adbd052ec8ff9cfd01ffb Mon Sep 17 00:00:00 2001 From: Ganawa Juanah Date: Sat, 8 Oct 2022 16:35:22 -0500 Subject: firewall: reduce line ending in rule-set --- docs/configuration/firewall/general.rst | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) (limited to 'docs') diff --git a/docs/configuration/firewall/general.rst b/docs/configuration/firewall/general.rst index efd5cb58..0cf8bcec 100644 --- a/docs/configuration/firewall/general.rst +++ b/docs/configuration/firewall/general.rst @@ -591,8 +591,8 @@ A Rule-Set can be applied to every interface: * ``out``: Ruleset for forwarded packets on an outbound interface * ``local``: Ruleset for packets destined for this router -.. cfgcmd:: set firewall interface [in | out | local] [name | ipv6-name] - +.. cfgcmd:: set firewall interface [in | out | local] [name | + ipv6-name] Here are some examples for applying a rule-set to an interface -- cgit v1.2.3